More hacking / email questions!

I've had multiple hosting accounts 'hacked' - where the hacker creates a NEW email address and proceeds to use that for sending spam...

I'm getting to know the Jodo abuse folks really well!

Is it possible to get info on when an email account was created, as well as the IP address it was created from?

These 'hackers' or attacks are coming from a similar source - whether that's the same person or a common script I don't know. The new email accounts have all been 'holmes' or 'uptask' or 'admin1' (sometimes all three!). I've seen these same email accounts created across multiple domians/hosting accounts, so there is definitely a common thread here.
 
Create a ticket with some domains, and I'll have Tanmaya and Pratik check this in logs, not a notice system in place, but please change your reseller admin password, we have seen them to be compromised a few times this last year, many from password stealing trojans in the past, or simply brute force.
 
Back
Top